First published: Mon Aug 07 2023(Updated: )
The Quiz And Survey Master WordPress plugin before 8.1.11 does not properly sanitize and escape question titles, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Expresstech Quiz And Survey Master | <8.1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3575 is a vulnerability in the Quiz And Survey Master WordPress plugin before version 8.1.11 that allows users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
The severity of CVE-2023-3575 is medium with a CVSS score of 5.4.
CVE-2023-3575 affects the Quiz And Survey Master plugin before version 8.1.11 by not properly sanitizing and escaping question titles, which enables Stored Cross-Site Scripting attacks.
To fix CVE-2023-3575 in the Quiz And Survey Master plugin, update it to version 8.1.11 or later.
More information about CVE-2023-3575 can be found at the following reference: https://wpscan.com/vulnerability/6f884688-2c0d-4844-bd31-ef7085edf112.